Securityaffairs

Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records


Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records

Pierluigi Paganini
August 06, 2026

Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims.

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars.

“Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims.” states DoJ.

The unnamed “U.S.-based software-as-a-service company” at the center of the scheme is Snowflake, the cloud data platform, though the DOJ press release doesn’t name it directly. Moucka was arrested just six months after the breaches began, which is either impressive law enforcement work or a sign that he wasn’t as careful as he thought.

“between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. Moucka and others used their unauthorized access to these customers’ computer systems to steal billions of sensitive customer records and download terabytes of information, including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information.” continues the DoJ’s press release.”They then extorted victims by threatening to publish data online.”

Moucka and his accomplices earned more than $2.5 million by extorting victims after stealing their data. In one case, they threatened to release information again, using stolen data belonging to a government official and family members to increase pressure.

They also sold stolen information on cybercrime forums and Telegram, allowing Moucka to personally gain at least $495,000. The attacks caused more than $9.5 million in direct losses for affected companies and exposed data linked to over 100 million individuals. Moucka pleaded guilty to computer fraud, wire fraud, identity theft, and conspiracy charges, and faces up to 30 years in prison.

The entry method wasn’t a sophisticated zero-day. The conspirators used stolen credentials, meaning accounts that weren’t protected by multi-factor authentication. That one missing control opened the door to what became one of the largest cloud data theft operations on record.

Re-extortion, going back to a victim who already paid and threatening them again, is a pattern that law enforcement has documented increasingly in ransomware and data theft cases. It works because victims are already compromised, the data is already gone, and the attacker has leverage as long as the data remains unpublished.

“Today’s guilty plea sends a clear message to cybercriminals: you cannot hide from justice, no matter how hard you may try to cover your tracks,” said Special Agent in Charge W. Mike Herrington of the FBI Seattle field office. “Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers. Ultimately, though, Mr. Moucka’s schemes were no match for the tenacity of FBI Seattle and this international investigative team. I am incredibly proud of their work. Let this outcome serve as a reminder: actions have consequences, and the FBI will continue to relentlessly pursue those who target American businesses and individuals in cyberspace, wherever they may be.”

Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a mandatory minimum of two years on the identity theft count and up to 30 years on the others. Sentencing is scheduled for October 27.

The man was extradited from Canada to the US in July 2025 with cooperation from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police, a list that tells you something about how international these criminal networks have become.

“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Moucka was arrested just six months after these breaches began, demonstrating this Department’s firm commitment to investigating and prosecuting sophisticated cybercriminals who cause extensive harm to American businesses and consumers. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)







Source link